Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 342

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Hayden Panettiere, who starred in ‘Heroes’ and ‘Nashville,’ dies at 36
OpenAI's Brockman brushes off concerns about leadership changes in CNBC exclusive
How to make my apartment feel less like an oven?
Medicaid estate recovery -- questions
Rick and Morty: A Ricker Runs Through It
Stanley Druckenmiller loaded up on Amazon and chip stocks before July rout
Movie: New York, New York
Nvidia backing $105 billion in financing for OpenAI data center in Ohio
Supreme Court again rejects Trump bid to overturn E. Jean Carroll verdict
Prediction market traders see roughly 1-in-4 odds Paramount’s bid to buy Warner Bros. Discovery fails